Wind River Support Network

HomeDefectsLIN1021-11143
Fixed

LIN1021-11143 : Security Advisory - apr - CVE-2023-49582

Created: Aug 28, 2024    Updated: May 25, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named shared memory segments, potentially revealing sensitive application data. 

This issue does not affect non-Unix platforms, or builds with APR_USE_SHMEM_SHMGET=1 (apr.h)

Users are recommended to upgrade to APR version 1.7.5, which fixes this issue.

CREATE(Triage):(User=admin) CVE-2023-49582 (https://nvd.nist.gov/vuln/detail/CVE-2023-49582)

CVEs


Live chat
Online